Forum Discussion
McAfee SIEM and ASM
I am trying to integrate McAfee SIEM and F5 ASM 11.2.1. However, the SIEM doesn't parse the logs correctly. After raising a ticket with McAfee, they said the issue is with the log format which is sending ';' as a delimiter instead of '|'. ASM is managed by customer's 3rd party and they have been interesting to deal with.
Below is the snippet of the logs, could you please confirm if the logging format is correct and if we can change the delimiter to '|'
<130>May 18 14:37:43 ASM.test.net ASM:ID=17934223281240667815;TYPE=Session Hijacking;DATE=2015-05-18 14:37:43;DEST_IP=10.X.X.X;DEST_PORT=443;GEO=NZ;HEADERS=Host: abcd.com\r\nAccept: text/html,application/xhtml+xml,application/xml;q=0.9,/;q=0.8\r\nConnection: keep-alive\r\nCookie: systemonline=rd1894o00000000000000000000ffff0ae82510o8081; TS23170d=b7a4548f02236bf5190c7a96708fe5af43b1ac33e4d3adb955595077a59b3514f8bf1008; TS553073=b9c1bdd560eba8c7c65346b59981217b361524825b09819e55595073a59b3514f8bf1008fd3b4071173028d4; __utma=18589601.539768155.1431916378.1431916378.1431916378.1; __utmb=18589601.6.10.1431916378; __utmc=18589601; __utmt=1; __utmz=18589601.1431916378.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)\r\nUser-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_2) AppleWebKit/600.3.18 (KHTML, like Gecko) Version/8.0.3 Safari/600.3.18\r\nAccept-Language: ja-jp\r\nReferer: https://xyz.com/system\r\nAccept-Encoding: gzip, deflate\r\nX-Forwarded-For: 1.2.3.4\r\nX-Forwarded-For: 1
2 Replies
- samstep
Cirrocumulus
Mahesh, whoever is managing the ASM need to configure the Logging Profile for your ASM policy to be in the format acceptable by McAfee SIEM - if it is a delimiter issue then it can be easily configured in the Logging Profile screen(just change semi-colon to pipe in the Delimiter field).
Only McAfee can tell you what is the correct format their device is expecting - you can them ask the ASM guys to configure the logging profile to match this format.
Hope this helps,
Sam
- samstep
Cirrocumulus
Mahesh, whoever is managing the ASM need to configure the Logging Profile for your ASM policy to be in the format acceptable by McAfee SIEM - if it is a delimiter issue then it can be easily configured in the Logging Profile screen(just change semi-colon to pipe in the Delimiter field).
Only McAfee can tell you what is the correct format their device is expecting - you can them ask the ASM guys to configure the logging profile to match this format.
Hope this helps,
Sam
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com